Website representations

A session recording can capture more than the checkout team intended

Establish the installed recorder's actual capture before trusting any description of its masking. Inventory the pages and fields it can see, decide which require exclusion, and verify the result with synthetic recordings in your own setup. Microsoft's Clarity documentation describes masking modes that govern recordings and notes that configuration changes affect new recordings rather than rewriting old ones; that is Clarity-specific and not a promise about every recorder. Masking is a technical control, not consent and not a privacy determination. Assign unverified fields and historical recordings to named owners.

For: An authorized owner or technical lead at a research-only store reviewing what an installed session-replay tool records on checkout, account and form pages.

Updated 2026-10-01

Inventory where the recorder runs and what it can see

Record which replay tool is installed, how it was deployed, its version and the pages it covers: checkout, cart, account, order confirmation and any contact or application forms. Note who installed it and who owns its configuration now. Teams often discover the recorder was added for a campaign and left running across pages nobody reviewed.

Replay tools reconstruct pages and interactions, so content rendered on a captured page can appear in a recording: names and addresses in account panels, free-text entries and order references are typical examples. Treat these as potentially exposed surfaces to verify against the actual recorder's documentation and its supported contexts, because capture depends on what the specific product supports and on browser boundaries; embedded or cross-origin content may be captured, partially captured or not captured at all, and masking exclusions are not the only limitation. List the surfaces explicitly instead of assuming the tool only sees form fields, check your installed tool's own documentation for what it captures by default because defaults differ between products, and record 'not captured' or 'unknown' outcomes where documentation or testing cannot settle a surface.

Decide which fields require exclusion

The business or privacy owner approves the exclusion list before anyone configures it. Candidates typically include contact fields, free-text boxes, order references, account details and embedded or third-party elements, which stay marked potentially exposed until verification shows whether the recorder actually captures them. Record field names and page locations only; never paste customer values into the review.

Do not let the tool's defaults make the decision for you. A field that ships unmasked by default is not thereby approved for capture, and a field masked by default is not thereby verified. Fields nobody has assessed stay marked unresolved until the owner decides, and that decision is what the configuration is then expected to implement.

Verify masking in your own setup

Microsoft's Clarity documentation describes masking modes that govern what recordings show, and states that masking changes affect new recordings rather than retroactively changing existing ones. Two limits follow. First, this is Clarity-specific: another recorder's masking must be checked against its own documentation. Second, a configured mode or selector expresses intent; it is not evidence of behavior in your theme and plugins.

Verify with a synthetic test: enter an invented value into each excluded field, generate a recording in your actual setup, and inspect the playback for that value. Record the date, pages, recorder version and browser conditions. A clean playback under stated conditions is the evidence you hold; it is not a universal guarantee across every page and device.

  • Test each excluded field with a synthetic value, not a real customer entry.
  • Inspect the actual playback, not only the configuration screen.
  • Record pages tested and pages left unexamined.

Keep masking separate from notice and consent

A working mask answers a narrow question: whether a field's content appears in new recordings. It does not answer whether recording should run on a page at all, what visitors should be told, or whether a consent mechanism applies. Those are separate questions for the qualified privacy owner, and a technical pass should never be reported as legal clearance.

If your site describes recording in a banner or policy, compare that wording with the verified behavior after this review, the same discipline used when comparing consent statements with tag behavior. A masking improvement and a wording correction can both be needed, and each has its own owner.

Assign corrections and scope any review

Three work items usually follow: the configuration change for fields that failed verification, the disposition of recordings captured before the change, and any wording correction. Because Clarity documents that changes apply to new recordings, historical recordings remain a live question with their own owner regardless of how clean the new tests look.

For a Prism website-review consultation, describe the website, the research-only catalog and a non-sensitive summary of the recorder and the fields at issue. Confirm which pages and questions are in scope, with responsibilities, fees and terms agreed before work. Do not share recordings, customer values or credentials through the public form; a content review is not a privacy-law opinion.

Recording-field review

Complete one review for the recorder actually installed. Use field names and page locations only. A field without a verified synthetic test stays unresolved, and recordings made before a correction stay a separate item. The final column is left for your dated record and owner.

Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.

Recording-field review. The last column is for temporary notes.
Review itemWhat to record and the decision it supportsYour record
Recorder installationTool name, version, deployment method and pages covered. Establishes what is actually deployed before judging its behavior.
Page surfaces in scopeCheckout, cart, account, confirmation and form pages the recorder can capture. Defines where field-level decisions are needed.
Field inventoryContact fields, free text and order references by field name only, plus embedded or third-party elements listed as potentially exposed surfaces, with each capture outcome recorded as captured, not captured or unknown after checking the actual recorder and its supported contexts. Lists exclusion candidates without recording customer values.
Exclusion decisionThe approved treatment for each field and its business owner. Separates an agreed decision from an assumed default.
Masking configurationThe configured mode or selector for each excluded field. A configured selector is intent, not proof of behavior.
Synthetic verificationDated test recording using an invented value in each excluded field, with playback inspected. Shows whether capture matches the decision in your setup.
Historical recordingsRecordings made before the correction and their disposition owner. Clarity documents that masking changes affect new recordings, so old captures are not rewritten.

These are temporary notes. Leaving or reloading this page may clear them. Worksheet entries are not sent automatically. If you copy notes into the consultation message and submit the form, Prism receives them as part of your request.

Limits

  • Clarity's masking documentation describes that named product; verify your own recorder against its own documentation instead of transferring the claim.
  • Masking configuration is not consent, notice or a legal determination; those questions need qualified privacy review.
  • A clean synthetic playback under stated conditions is narrow evidence; record the pages and conditions examined.
  • Keep real recordings, customer values and credentials out of the worksheet and the public consultation form.

Sources

  • Microsoft Clarity: Content masking — checked 2026-10-01. Clarity documents masking modes that govern what recordings show, and that masking changes affect new recordings rather than retroactively changing existing ones. The guidance is specific to Clarity.
  • Prism features — checked 2026-09-21. Published website-review scope covers product descriptions, marketing claims, store policies and business disclosures; findings are informational, not legal opinions or compliance certification.

Request a website review

Want a second look at your own storefront pages?